#VU125337 Use-after-free in libyang
Published: April 8, 2026
libyang
CESNET
Description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in the XML data parser when parsing a crafted YANG XML document with specific metadata attributes. A remote user can send a specially crafted XML document to cause a denial of service.
Applications parsing attacker-controlled or semi-trusted XML-encoded YANG instance data are affected, including NETCONF, RESTCONF, and configuration import scenarios.